From patchwork Fri Oct 16 05:52:48 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Fabrice Fontaine X-Patchwork-Id: 1383070 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.136; helo=silver.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=UHkp3O1n; dkim-atps=neutral Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4CCFgZ1cYhz9sTK for ; Fri, 16 Oct 2020 16:53:13 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id C35222E400; Fri, 16 Oct 2020 05:53:10 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2EIlQuLZBQut; Fri, 16 Oct 2020 05:53:06 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by silver.osuosl.org (Postfix) with ESMTP id E9DCA2E285; Fri, 16 Oct 2020 05:53:05 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from fraxinus.osuosl.org (smtp4.osuosl.org [140.211.166.137]) by ash.osuosl.org (Postfix) with ESMTP id DC28D1BF860 for ; Fri, 16 Oct 2020 05:53:03 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by fraxinus.osuosl.org (Postfix) with ESMTP id D8E8E8886D for ; Fri, 16 Oct 2020 05:53:03 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from fraxinus.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0QlBLdRIpPH9 for ; Fri, 16 Oct 2020 05:53:02 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by fraxinus.osuosl.org (Postfix) with ESMTPS id 81A6888864 for ; Fri, 16 Oct 2020 05:53:02 +0000 (UTC) Received: by mail-wr1-f46.google.com with SMTP id y12so1300557wrp.6 for ; Thu, 15 Oct 2020 22:53:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=41yIgdHaytsZfWBx4vGXQB2ltI9R+SDpO8NiOPleGQk=; b=UHkp3O1na0lDnP5xcjFrt5vKwprABIZsV07j+feRkJR+JS1teJMEOsieOim5LWzqC8 VBMb+hAtTSENJ3BWHfaxpEKeViat+QxtvKl4sW+LKJyuhP/P7C0Zv9wKkbAquitE03mX 7OH7feP+UPMXeDc120Qp2kE9vLQCEmGNCIXZETJEEECg7zM4+WJrGYPBBM6lCE1yFbxL cTNF1zjfSM86kpP4JTXLwulHng9sfOkmBCLz33F3i0q3N9J6gG+65Xv/ZK63n9pW0FgA D40RBIhpmPnPr8KscxNoC9K6rLBvmCRhYr2+ZsbYStNFW7WHVQVYc9U7oR+KmLEpasG5 rkNg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=41yIgdHaytsZfWBx4vGXQB2ltI9R+SDpO8NiOPleGQk=; b=esNNngoMtghQMKXFqTNbXnC1NFh1LSIdylQS39ruC0Fmp9QeGJICySlp/GgAKHmWNE xTq9fZHcXcW0TCCfS1FCCvU5uAfvgAwFci4ikUuVZlVc2zXurO1IqBgpcWX8sGujxZ5p Edhd2MiCNwPNZo+WpHM522nvsQKTQF+4667dt3blPwYzPjjq7xHotZhM/26WaRapQJZ3 PKdRaxYesX0j4GAwQpGcvEz3yXlDA7Qltns32/qAkaz3zhLaVBDAiLZ0zTDnN0LzrC8U UXVz20X50mjLr7bwTNNIjbHixy5uEccovdLBj68U7BiG5DWlYAHrE/ljKPfK6w2SJC8P Gg3w== X-Gm-Message-State: AOAM531WylNw7xKHBOsl++Z/WYqy/3D8Dm4ucXBnfa/g6bskHoFGEWUF a5XgZhUm8kkzbMiju3xTfJYi2xUcOcIHxw== X-Google-Smtp-Source: ABdhPJz7k7C6OjHt5BA3h55FTN/7JKdurCIhVE1ALI2+U6Hb6q7g+7pbNdi88EXr7AF70M6w8Wm1oA== X-Received: by 2002:adf:a306:: with SMTP id c6mr1831897wrb.160.1602827580562; Thu, 15 Oct 2020 22:53:00 -0700 (PDT) Received: from kali.home (2a01cb0881b76d00c2afd0dfa851d2b9.ipv6.abo.wanadoo.fr. [2a01:cb08:81b7:6d00:c2af:d0df:a851:d2b9]) by smtp.gmail.com with ESMTPSA id 14sm1347104wmf.27.2020.10.15.22.52.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 15 Oct 2020 22:52:59 -0700 (PDT) From: Fabrice Fontaine To: buildroot@buildroot.org Date: Fri, 16 Oct 2020 07:52:48 +0200 Message-Id: <20201016055248.1968370-1-fontaine.fabrice@gmail.com> X-Mailer: git-send-email 2.28.0 MIME-Version: 1.0 Subject: [Buildroot] [PATCH 1/1] package/libcroco: drop package X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Fabrice Fontaine Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Drop libcrococo as it is affected by several security issues such as CVE-2020-12825 which will never be fixed as this project has been archived: https://gitlab.gnome.org/Archive/libcroco/-/issues/8 Signed-off-by: Fabrice Fontaine --- Config.in.legacy | 8 ++++++++ package/Config.in | 1 - package/libcroco/Config.in | 20 -------------------- package/libcroco/libcroco.hash | 5 ----- package/libcroco/libcroco.mk | 21 --------------------- 5 files changed, 8 insertions(+), 47 deletions(-) delete mode 100644 package/libcroco/Config.in delete mode 100644 package/libcroco/libcroco.hash delete mode 100644 package/libcroco/libcroco.mk diff --git a/Config.in.legacy b/Config.in.legacy index da48757143..a620005d2e 100644 --- a/Config.in.legacy +++ b/Config.in.legacy @@ -146,6 +146,14 @@ endif comment "Legacy options removed in 2020.11" +config BR2_PACKAGE_LIBCROCO + bool "libcroco package was removed" + select BR2_LEGACY + help + This package has been removed as it is affected by several + security issues such as CVE-2020-12825 which will never be + fixed as libcroco has been archived. + config BR2_PACKAGE_BELLAGIO bool "bellagio package was removed" select BR2_LEGACY diff --git a/package/Config.in b/package/Config.in index 357c9e1097..673ececf37 100644 --- a/package/Config.in +++ b/package/Config.in @@ -1863,7 +1863,6 @@ menu "Other" source "package/libclc/Config.in" source "package/libcofi/Config.in" source "package/libcorrect/Config.in" - source "package/libcroco/Config.in" source "package/libcrossguid/Config.in" source "package/libcsv/Config.in" source "package/libdaemon/Config.in" diff --git a/package/libcroco/Config.in b/package/libcroco/Config.in deleted file mode 100644 index ad78a147e4..0000000000 --- a/package/libcroco/Config.in +++ /dev/null @@ -1,20 +0,0 @@ -config BR2_PACKAGE_LIBCROCO - bool "libcroco" - depends on BR2_USE_WCHAR # glib2 - depends on BR2_TOOLCHAIN_HAS_THREADS # glib2 - depends on BR2_USE_MMU # glib2 - select BR2_PACKAGE_LIBXML2 - select BR2_PACKAGE_LIBGLIB2 - help - Libcroco is a standalone css2 parsing and manipulation - library. The parser provides a low level event driven SAC - like api and a css object model like api. - - Libcroco provides a CSS2 selection engine and an - experimental xml/css rendering engine. - - https://github.com/GNOME/libcroco - -comment "libcroco needs a toolchain w/ wchar, threads" - depends on BR2_USE_MMU - depends on !BR2_USE_WCHAR || !BR2_TOOLCHAIN_HAS_THREADS diff --git a/package/libcroco/libcroco.hash b/package/libcroco/libcroco.hash deleted file mode 100644 index b998206422..0000000000 --- a/package/libcroco/libcroco.hash +++ /dev/null @@ -1,5 +0,0 @@ -# From http://ftp.acc.umu.se/pub/gnome/sources/libcroco/0.6/libcroco-0.6.13.sha256sum -sha256 767ec234ae7aa684695b3a735548224888132e063f92db585759b422570621d4 libcroco-0.6.13.tar.xz - -# Hash for license file: -sha256 94b03f1a60a7fd5007149530626a895a6ef5a8b9342abfd56860c5f3956f5d23 COPYING.LIB diff --git a/package/libcroco/libcroco.mk b/package/libcroco/libcroco.mk deleted file mode 100644 index c717c9a212..0000000000 --- a/package/libcroco/libcroco.mk +++ /dev/null @@ -1,21 +0,0 @@ -################################################################################ -# -# libcroco -# -################################################################################ - -LIBCROCO_VERSION_MAJOR = 0.6 -LIBCROCO_VERSION = $(LIBCROCO_VERSION_MAJOR).13 -LIBCROCO_SITE = http://ftp.gnome.org/pub/gnome/sources/libcroco/$(LIBCROCO_VERSION_MAJOR) -LIBCROCO_SOURCE = libcroco-$(LIBCROCO_VERSION).tar.xz -LIBCROCO_INSTALL_STAGING = YES -LIBCROCO_DEPENDENCIES = host-pkgconf libglib2 libxml2 -HOST_LIBCROCO_DEPENDENCIES = host-pkgconf host-libglib2 host-libxml2 -LIBCROCO_CONFIG_SCRIPTS = croco-$(LIBCROCO_VERSION_MAJOR)-config -# NEWS states that it's only LGPL -# Source code says v2.1+ even though COPYING.LIB is v2 -LIBCROCO_LICENSE = LGPL-2.1+ -LIBCROCO_LICENSE_FILES = COPYING.LIB - -$(eval $(autotools-package)) -$(eval $(host-autotools-package))